IS Security GRC Platform Engineer - Remote
Ochsner Health · New Orleans, LA · 1 mo ago
EngineeringFull-time
About the role
We are seeking a Cybersecurity GRC Engineer to join our dynamic team at Ochsner Health. Our mission is to serve, heal, lead, educate, and innovate, and we are looking for someone who shares our commitment to excellence.
Responsibilities
- Serves as a technical and functional administrator for the Cybersecurity GRC application, Onspring.
- Maintains and enhances Onspring workflows, forms, dashboards, reports, data fields, notifications, user access, control libraries, risk records, finding records, evidence repositories, and security exception processes.
- Supports integration and coordination between Onspring and related applications, workflow tools, reporting tools, ticketing platforms, and enterprise data sources.
- Designs, configures, tests, documents, and deploys new or enhanced GRC workflows to support cybersecurity risk management, compliance tracking, audit readiness, control assessments, third-party risk, remediation management, and executive reporting.
- Maintains cybersecurity framework mappings and control documentation aligned with NIST, HIPAA, ISO/IEC 27001, HITRUST, PCI DSS, SOC 2, FedRAMP, FISMA, DFARS, CIS Controls, and other applicable requirements.
- Supports audit readiness activities by coordinating evidence collection, validating control documentation, tracking findings, supporting corrective action plans, and monitoring remediation activities.
- Supports POA&M, corrective action, findings, issues, exceptions, and remediation tracking to ensure assigned actions are documented, monitored, escalated, and reported appropriately.
- Partners with Cybersecurity, Information Services, Audit, Compliance, Privacy, Legal, third-party risk, and business stakeholders to improve GRC processes and strengthen control visibility.
- Develops and maintains executive-level reports, dashboards, metrics, and status updates for risk posture, remediation progress, audit readiness, control performance, and GRC program health.
- Creates and maintains process documentation, workflow diagrams, job aids, templates, user guides, playbooks, and training materials for Onspring and related GRC processes.
- Collaborates with vendors or internal application teams to troubleshoot platform issues, evaluate enhancement requests, resolve workflow problems, and support platform improvements.
- Supports third-party risk management, policy and standard lifecycle activities, privileged access reviews, security exception management, audit response, compliance monitoring, and other Cybersecurity GRC program activities as assigned.
- Identifies continuous improvement opportunities to standardize data quality, improve workflow adherence, increase platform adoption, automate manual processes, and improve reporting reliability.
Requirements
- Education: High school diploma or equivalent.
- Experience: 2 years information technology experience with master’s degree; OR 4 years information technology experience with bachelor’s degree; OR 6 years information technology experience with associate’s degree; OR 8 years of information technology experience.
- Preferred: 5 to 10 years of related information technology, cybersecurity, governance, risk, compliance, audit, security operations, application administration, or platform administration experience in a regulated industry.
- Preferred: Experience supporting cybersecurity GRC functions in healthcare, federal, government, commercial, or other highly regulated environments.
- Preferred: Experience with GRC and workflow platforms such as Onspring, Archer, MetricStream, Xacta, CSAM, ServiceNow, JIRA, Confluence, Remedy, or similar platforms.
- Knowledge: Working knowledge of GRC platform administration, preferably Onspring, including workflow configuration, form design, dashboards, reporting, data quality management, user support, control mapping, risk tracking, findings management, evidence management, and integration with related enterprise applications.
Qualifications
- Strong knowledge of cybersecurity and compliance frameworks and standards, including NIST CSF, NIST RMF, NIST SP 800-53, NIST SP 800-171, HIPAA, ISO/IEC 27001, SOC 2, HITRUST, FedRAMP, FISMA, DFARS, PCI DSS, and CIS Controls.
- Ability to translate regulatory, audit, technical, and business requirements into repeatable GRC workflows, clear documentation, measurable control activities, and actionable reporting.
- Ability to support third-party risk management activities, including vendor assessments, inherited risk reviews, control validation, remediation monitoring, and compliance documentation.
- Strong verbal, written, diagrammatic, and executive communication skills, including the ability to prepare dashboards, metrics, summaries, process documentation, playbooks, templates, and leadership-level reporting.
- Strong organization, documentation, follow-through, analytical, and continuous service improvement skills with the ability to manage multiple priorities and maintain audit-ready records.
- Ability to work independently and as part of a cross-functional team in a fast-paced healthcare environment.
- Ability to work a flexible schedule, including occasional after-hours, weekends, holidays, on-call support, or urgent compliance and cybersecurity activities as required by business needs.
Skills
- Working knowledge of GRC platform administration, preferably Onspring, including workflow configuration, form design, dashboards, reporting, data quality management, user support, control mapping, risk tracking, findings management, evidence management, and integration with related enterprise applications.
- Experience with GRC platforms and related workflow tools such as Onspring, Archer, MetricStream, Xacta, CSAM, ServiceNow, JIRA, Confluence, Remedy, or similar systems.
- Strong knowledge of cybersecurity and compliance frameworks and standards, including NIST CSF, NIST RMF, NIST SP 800-53, NIST SP 800-171, HIPAA, ISO/IEC 27001, SOC 2, HITRUST, FedRAMP, FISMA, DFARS, PCI DSS, and CIS Controls.
- Experience supporting audit readiness, evidence collection, control testing, corrective action plans, POA&Ms, remediation tracking, executive reporting, and continuous monitoring activities.
- Ability to support third-party risk management activities, including vendor assessments, inherited risk reviews, control validation, remediation monitoring, and compliance documentation.
- Strong verbal, written, diagrammatic, and executive communication skills, including the ability to prepare dashboards, metrics, summaries, process documentation, playbooks, templates, and leadership-level reporting.
- Strong organization, documentation, follow-through, analytical, and continuous service improvement skills with the ability to manage multiple priorities and maintain audit-ready records.
- Ability to work independently and as part of a cross-functional team in a fast-paced healthcare environment.
- Ability to work a flexible schedule, including occasional after-hours, weekends, holidays, on-call support, or urgent compliance and cybersecurity activities as required by business needs.